Controls & ComplianceCRI ProfileCoverage AssessmentFinancial ServicesAI-Assisted

CRI Coverage Assessment — PR.AA-01.01

Turn regulatory requirements into evidence-traceable coverage decisions. A governed, AI-assisted assessment of 568 institutional controls against 16 CRI v2.2 Identity and Credential Management capabilities — producing reproducible coverage conclusions, structured findings, remediation priorities, and a complete human-review audit trail. Every conclusion traceable. Every judgment reviewable. No client data leaves the environment.

Updated 2026-07-19

Interactive artifacts included below — Full Assessment Workpaper, Methodology Architecture, Assessment Pipeline Prompts.

Synthetic Demonstration

Heritage Community Bank is a fictional institution. All data, controls, findings, and regulatory matters shown here are simulated for research and portfolio purposes.

Context

Regulatory coverage assessments have a structural problem. Framework requirements are written differently from institutional controls. Traditional mapping approaches often rely on keywords, spreadsheets, and analyst interpretation — making it difficult to demonstrate why a control satisfies a requirement or reproduce the conclusion during challenge. The problem is not simply finding controls. The problem is producing defensible evidence that the right controls satisfy the right requirements — and preserving the reasoning behind every conclusion. This assessment demonstrates a governed methodology for doing that systematically.

Scope

1 CRI Diagnostic Statement  ·  16 decomposed Response Guidance capabilities  ·  568 institutional controls  ·  32 SCF-aligned control domains  ·  9,088 potential requirement-to-control relationships before intelligent selection Sixteen requirements × 568 controls = 9,088 potential relationships. The objective was not to maximize mappings. It was to identify the smallest defensible set of controls supporting each requirement and determine whether the resulting evidence demonstrated Covered, Partial, or No Coverage.

Methodology

The assessment follows a four-layer governed architecture: 1 — Knowledge. CRI v2.2 source requirements, decomposed capabilities, institutional controls, and structured control metadata establish the authoritative assessment context. 2 — Reasoning. Candidate controls are selected based on capability relevance — not keyword similarity alone. Each requirement is evaluated against supporting controls and produces a structured Coverage Decision Record documenting evidence, rationale, gaps, and verdict. 3 — Quality Assurance. Evidence quotations are verified against source controls. Rating consistency and assessment completeness are tested before conclusions are released. 4 — Human Judgment & Reporting. Senior reviewers can concur, override, or flag individual conclusions. Human decisions are preserved alongside AI-generated analysis, producing an auditable record of professional judgment.

The Unit of Accountability: Coverage Decision Record

Every coverage conclusion produces a structured decision record containing: Requirement → Candidate Controls → Evidence → Capability Match → Gap → Rationale → Verdict → Human Review The result is not simply a mapping. It is a reproducible record of why the mapping was accepted. When challenged — "Why did you rate this Partial?" — the record opens to demonstrate the full chain. That is auditability applied to AI-assisted reasoning.

Results

568 controls analyzed  ·  16 capabilities assessed  ·  5 / 16 Covered  ·  11 / 16 Partial  ·  0 / 16 No Coverage  ·  19 structured findings The assessment found broad control presence but uneven capability completeness: every CRI requirement had some supporting coverage, yet 69% remained Partial because one or more required capabilities were insufficiently demonstrated. Strengths: identity lifecycle management, credential requirements, access provisioning. Priority gaps: service-account governance, continuous privilege monitoring, automated access certification.

From Mapping to Defensible Assessment

Traceable by design. Every verdict links to supporting controls, quoted evidence, rationale, identified gaps, and its Coverage Decision Record. Human accountable. AI accelerates analysis; it does not own the conclusion. Review Mode allows senior reviewers to concur, override, or flag decisions with a preserved audit trail. Private by architecture. Sensitive institutional controls remain inside the client environment. Local inference prevents control descriptions and evidence from being transmitted to external AI services. Reproducible. The same requirement, evidence, and methodology can be reconstructed and challenged rather than relying on undocumented analyst interpretation. Reusable. Structured control intelligence from the Control Profiler creates foundations that support additional CRI Diagnostic Statements and other frameworks — one governed pipeline from unstructured controls to defensible coverage decisions.

What I Would Discuss in an Interview

The system doesn't automate professional judgment. It makes professional judgment traceable, reproducible, and reviewable. How the Coverage Decision Record changes the conversation from "the AI determined..." to opening the full evidence chain. Why 9,088 potential relationships required intelligent selection, not brute-force mapping. How the four-layer architecture separates knowledge, reasoning, quality, and human accountability. Why the Control Profiler and CRI Assessment form one governed pipeline — structure controls, then assess them — rather than two independent projects.

Artifacts